2014年3月25日火曜日

25日 火曜日、友引

+ RHSA-2014:0321 Moderate: net-snmp security and bug fix update
http://rhn.redhat.com/errata/RHSA-2014-0321.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2284

+ Mozilla Firefox 28.0.1 released
http://www.mozilla.org/en-US/firefox/28.0/releasenotes/

+ MFSA 2014-33 File: protocol links downloaded to SD card by default
http://www.mozilla.org/security/announce/2014/mfsa2014-33.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1515

+ iTunes 11.1.5 released
http://www.apple.com/itunes/download/

+ CESA-2014:0316 Important CentOS 5 thunderbird Update
http://lwn.net/Alerts/591184/

+ CESA-2014:0316 Important CentOS 6 thunderbird Update
http://lwn.net/Alerts/591183/

+ phpMyAdmin 4.1.11 is released
http://sourceforge.net/p/phpmyadmin/news/2014/03/phpmyadmin-4111-is-released/

+ Linux kernel 3.13.7, 3.10.34, 3.4.84 released
https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.13.7
https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.34
https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.4.84

+ RHSA-2014:0322 Moderate: net-snmp security update
http://rhn.redhat.com/errata/RHSA-2014-0322.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6151
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2285

+ PostgreSQL updates 9.3.4, 9.2.8, 9.1.13, 9.0.17, and 8.4.21 released
http://www.postgresql.org/about/news/1511/
http://www.postgresql.org/docs/9.3/static/release-9-3-4.html
http://www.postgresql.org/docs/9.2/static/release-9-2-8.html
http://www.postgresql.org/docs/9.1/static/release-9-1-13.html
http://www.postgresql.org/docs/9.0/static/release-9-0-17.html
http://www.postgresql.org/docs/8.4/static/release-8-4-21.html

+ Microsoft Word RTF File Processing Flaw Let Remote Users Execute Arbitrary Code
http://www.securitytracker.com/id/1029948
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1761

+ PHP Null Pointer Dereference in libgd gdImageCreateFromXpm() Lets Remote Users Deny Service
http://www.securitytracker.com/id/1029947
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2497

+ Linux Kernel Netfilter DCCP Processing Flaw Lets Remote Users Execute Arbitrary Code
http://www.securitytracker.com/id/1029945
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2523

+ Google Chrome Bugs Let Remote Users Execute Arbitrary Code
http://www.securitytracker.com/id/1029940
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1705
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1713
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1714
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1715

+ REMOTE: MS14-012 Internet Explorer TextRange Use-After-Free
http://www.exploit-db.com/exploits/32438

+ DoS/PoC: Windows Media Player 11.0.5721.5230 - Memory Corruption PoC
http://www.exploit-db.com/exploits/32477

+ SA57541 Linux Kernel SCTP Handshake NULL Pointer Dereference Vulnerability
http://secunia.com/advisories/57541/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0101

+ SA57542 Linux Kernel "keyring_detect_cycle_iterator()" Denial of Service Vulnerability
http://secunia.com/advisories/57542/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0102

+ SA57284 Linux Kernel "rds_ib_laddr_check()" NULL Pointer Dereference Vulnerability
http://secunia.com/advisories/57284/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7339

+ SA57488 OpenSSH "child_set_env()" Security Bypass Security Issue
http://secunia.com/advisories/57488/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2532

+ SA57091 OpenSSL ECDSA Nonces Recovery Weakness
http://secunia.com/advisories/57091/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0076

+ Linux Kernel potential information leak when ubuf backed skbs are skb_zerocopy()
http://cxsecurity.com/issue/WLB-2014030180
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2568

+ Microsoft Internet Explorer TextRange Use-After-Free (MS14-012) Exploit
http://cxsecurity.com/issue/WLB-2014030176
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0307

+ Linux Kernel rds prevent dereference of a NULL device
http://cxsecurity.com/issue/WLB-2014030169
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7339

+ Microsoft Word CVE-2014-1761 Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/66385
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1761

+ OpenSSH 'child_set_env()' Function Security Bypass Vulnerability
http://www.securityfocus.com/bid/66355
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2532

+ Linux Kernel CVE-2014-2568 Information Disclosure Vulnerability
http://www.securityfocus.com/bid/66348
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2568

+ Linux Kernel CVE-2013-7339 NULL Pointer Dereference Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/66351
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7339

ウイルスバスタービジネスセキュリティサービス 5.3 Service Pack 1公開のお知らせ
http://app.trendmicro.co.jp/support/news.asp?id=2098

JVNDB-2014-000033 ES File Explorer におけるディレクトリトラバーサルの脆弱性
http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-000033.html

JVNDB-2014-000032 Silex におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-000032.html

JIAA、インターネット広告のプライバシーポリシーガイドラインを9年ぶりに改定
http://itpro.nikkeibp.co.jp/article/NEWS/20140325/545622/?ST=security

「攻撃者は必ず痕跡を消そうとする」、トレンドマイクロが実際の攻撃から解析
http://itpro.nikkeibp.co.jp/article/NEWS/20140324/545582/?ST=security

[続報]KADOKAWAへの不正アクセス、大手銀行を装うフィッシングが目的
http://itpro.nikkeibp.co.jp/article/NEWS/20140324/545503/?ST=security

「KADOKAWA」のサーバーに再び不正アクセス、フィッシングの踏み台に
http://itpro.nikkeibp.co.jp/article/NEWS/20140324/545282/?ST=security

トルコ政府のTwitter遮断は成果無し、いっそう高まる批判---海外メディアの報道
http://itpro.nikkeibp.co.jp/article/NEWS/20140324/545262/?ST=security

REMOTE: Horde Framework Unserialize PHP Code Execution
http://www.exploit-db.com/exploits/32439

REMOTE: Array Networks vAPV and vxAG Private Key Privelege Escalation Code Execution
http://www.exploit-db.com/exploits/32440

DoS/PoC: jetVideo 8.1.1 - Basic (.wav) Local Crash PoC
http://www.exploit-db.com/exploits/32478

DoS/PoC: Light Audio Player 1.0.14 - Memory Corruption PoC
http://www.exploit-db.com/exploits/32481

DoS/PoC: GOM Media Player (GOMMP) 2.2.56.5183 - Memory Corruption PoC
http://www.exploit-db.com/exploits/32482

DoS/PoC: GOM Video Converter 1.1.0.60 - Memory Corruption PoC
http://www.exploit-db.com/exploits/32483

0 件のコメント:

コメントを投稿